Azure / azhpc-images

Azure HPC/AI VM Images
MIT License
95 stars 77 forks source link

Create disable_user_namespaces.sh #297

Closed darkwhite29 closed 9 months ago

darkwhite29 commented 9 months ago

As a security patch of the Common Vulnerabilities and Exposures (CVE) issue for AlmaLinux-HPC 8.7 only, per internal discussion and RHEL official solutions:

https://access.redhat.com/security/cve/cve-2023-32233

xpillons commented 3 months ago

@darkwhite29 this breaks enroot execution which needs usernamespace to be enabled as explained here https://github.com/NVIDIA/enroot/blob/master/doc/requirements.md#kernel-settings